>samit_hota
Back to security news
SN-2026-281HighOpen

ExfilSquad Extorts UK Police Database, Leaking 135,000 Officer Contact Records

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Police National Legal Database (PNLD), UK Home Office Police Forces, Ask the Police
#news#data-breach#uk

The U.K.’s Police National Legal Database breach has exposed the contact details of over 100,000 police officers, criminal justice staff, and government partners after being targeted by a data extortion group. The service, which has operated for over 30 years as the primary legal information resource for all 43 Home Office police forces in England and Wales as well as the British Transport Police, confirmed that unauthorized third parties accessed subscriber contact directories and public inquiry data.

The intrusion was initially detected on Sunday, July 26. Shortly thereafter, the threat group calling itself ExfilSquad claimed responsibility for the breach, releasing sample data to validate its claims and demanding a ransom payment to prevent the publication of the remaining exfiltrated files.

Details of the Exfiltration

According to statements from PNLD and public claims published by ExfilSquad, the compromised data totals approximately 1.9 GB across roughly 135,000 individual records. The stolen dataset is divided into two distinct pools:

  • PNLD Subscribers (~114,000 records): Includes full names, affiliated organizations, and official email addresses of police officers, law enforcement staff, government partner personnel, and criminal justice professionals across the United Kingdom.
  • Ask the Police Users (~21,000 records): Includes names and email addresses of members of the public who submitted legal or policing inquiries through the public-facing ‘Ask the Police’ portal operated by PNLD.

PNLD confirmed that the service does not store classified investigative files, operational case notes, or confidential information regarding victims, witnesses, or offenders. Consequently, no operational law enforcement files or victim records were impacted. Furthermore, preliminary forensic investigations indicate that account passwords, hashes, and active authentication credentials remained uncompromised during the incident.

Blast Radius and Threat Actor Profile

While the absence of stored credentials and sensitive case files caps the immediate technical severity, the blast radius of this compromise is strategically significant. PNLD functions as a shared legal repository across every regional police force in England and Wales. The exposure of a verified, highly accurate directory of over 100,000 active officers and support staff provides threat actors with an extensive directory for secondary targeting.

ExfilSquad is a data extortion entity known for targeting commercial and public organizations to exfiltrate bulk sensitive datasets for financial extortion. The group recently claimed responsibility for an attack on American semiconductor manufacturer Analog Devices, demonstrating a pattern of targeting infrastructure organizations and leveraging stolen datasets as leverage without relying on destructive ransomware deployment.

In attacks targeting centralized administrative directories, extortion groups typically exploit web application vulnerabilities, misconfigured cloud storage endpoints, or stolen administrative portal credentials to pull tabular user databases via automated API calls or SQL injection vectors.

Tactical Risks: Social Engineering and OSINT Exploitation

From a defense perspective, the chief operational risk arising from the PNLD breach is not direct system takeover, but targeted social engineering against U.K. criminal justice personnel.

Mass exposure of verified corporate email addresses paired with full names and institutional affiliations drastically lowers the barrier for high-efficacy spear-phishing, credential harvesting, and business email compromise (BEC) attacks targeting individual forces. Threat actors can easily cross-reference the leaked PNLD dataset with open-source intelligence (OSINT)—such as professional social media profiles—to craft highly tailored phishing lures disguised as internal police communications, legal updates, or judicial notices.

Additionally, public users who submitted questions to the ‘Ask the Police’ platform face heightened risk of targeted phishing impersonating U.K. police services or legal authorities asking for follow-up details on legal inquiries.

Response and Ongoing Remediation

PNLD has notified all affected police forces, partner institutions, and the U.K. Information Commissioner’s Office (ICO) in accordance with statutory reporting requirements. Forensic analysis and containment efforts are being managed alongside cybersecurity specialists and the U.K. National Crime Agency (NCA).

Security teams overseeing domains affected by the leak should proactively implement the following operational defenses:

  • Heighten Phishing Alert Levels: Defensive teams across U.K. police forces and justice partners should prepare email filtering gateways for an influx of targeted spear-phishing campaigns mimicking PNLD legal bulletins, administrative notices, or internal IT service desks.
  • Implement Strict DMARC and Email Authentication: Organizations affiliated with the breach should verify that strict DMARC enforcement (p=reject), SPF, and DKIM alignment are configured across all departmental domains to prevent external threat actors from spoofing official police email addresses.
  • User Awareness Notification: Personnel whose contact details were included in the PNLD subscriber base should be advised to exercise heightened skepticism regarding unsolicited internal-themed emails, external links, or secondary requests for login credentials.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call